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This listing of claims will replace all prior versions, and listings, of claims in the application: 
Listing of Claims: . — ■ - — . 



1 . (Presently Amended): A method for controlling access, use and distribution of personal 
data of a user stored in a personal repository, the method comprising the steps of: 

receiving input defining personal data comprising a master profile and one or more 
service profiles for storage in the personal repository, the master profile and one or more service 
profiles corresponding to the user; 

receiving user input identifying one allowing th e us e r to indicat e which portions of th e 
p e rsonal dat a of the service profiles stored in the personal data repository ar e r e l e asabl eas 
corresponding to a second party; 

reaching an agreement, between the user and the second party, regarding user-b yrelease to 
the second party r _of any portion s of th e personal dat a the identified service profile in th e p e rsonal 
data repository ; and 

r e l e a s in g providing any of th e portions of th e stor e d p e rsonal dat a the identified service 
profile ffl-from the personal data repository to the second party according to the agreement.^ 
wh e r e in 

the agreement includ e s what it e m s within the personal data r e pository can bo used by the 

second party, and 

only on e s of th e it e ms which, according to th e agr ee m e nt, can bo used by th e s e cond 

party ar e releas e d to th e s e cond party. 

2. (Presently Amended): The method of claim 1, wherein the personal data about th e us e r is 
collected automatically comprises automatically collected information . 

3. (Original): The method of claim 1 , wherein the step of reaching the agreement 
comprises choosing an agreement provided by an independent agreement provider, wherein the 
independent agreement provider receives compensation based on use of the provided agreement. 
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4. (Presently Amended): The method of claim 1, wherein the personal data about th e us e r 
^ comprises information entered by the user. 

5. (Presently Amended): The method of claim 1 , further comprising the step of storing the 
personal data about th e us e r on a device operated by the user. 

6. (Presently Amended): The method of claim 1, further comprising the step of storing the 
personal data about th e us e r on a trusted party device. 

7. (Presently Amended): The method of claim 1, further comprising the step of storing the 
personal data about th e us e r in a distributed manner among a plurality of trusted party devices. 

8 . (Presently Amended) : The method of claim 1 , further comprising th e st e p of allowing th e 
u se r to p e rform at l e ast on e of adding, d e l e ting or changing th e p e rsonal dat a wherein the 
identified service profile comprises music preferences about th e u s er . 

9. (Presently Amended): The method of claim 1 , wherein the second party comprises a 
financial institution, and wherein the identified service profile comprises financial 
information. furthor comprising the step of d e fining a service profile within th e p e rsonal data 
r e pository, wherein th e s e ndee profile includ e s portions of the p e rsonal data of th e us e r and 
information regarding conditions und e r which it e ms within th e s e rvic e profile can be us e d by th e 
second party. 

10. (Presently Amended): The method of claim 9, wherein the identified service profile 
includes information regarding a date and a time that any of the stored-information about th e 
user- in the identified service profile was released to the second party and to whom the stored 
information was released. 
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1 1 . (Presently Amended): The method of claim 9, wherein the identified service profile 
includes information pertaining to a description of the agreement between the user and the 
second party. 

12. (Original): The method of claim 1 , further comprising the step of acting, by a trusted 
party, as an agent of the user to negotiate use, by the second party, of any of the personal data of 
the v ser in return for compensation to the user for the use of any of the personal data. 

13. (Presently Amended): The method of claim 4-2, further comprising the steps of 
automatically recording a history of actions^ by the user using a user device, as part of the 
personal data of the user. 

14. (Presently Amended): The method of claim 13, further comprising d e fining, by th e u se r, 
of a l e v e l of a typ e receiving user input defining a type of the-actions to be automatically 
recorded. 

15. (Presently Amended): The method of claim 1, further comprising the steps of: 
receiving, at a trusted party device connected to a computer network, a first request from 

a device operated by a-the user; 

forming a second request £effl -based on the first request, the second request being 
stripped of information that can associate the user with the second request; 

sending, from the trusted party device, the second request over a computer network to a 
second party device; 

receiving, at the trusted party device, response information in response to the sending of 
the second request; 

forming a response based on the response information; and 
sending the response to the device operated by the user. 

16. (Canceled) 
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17. (Canceled) 

18. (Presently Twice Amended): A system for providing personal data of a user with access 
rights being controlled by the user, the system comprising: 

a user device; 

a trusted party device, the user device being arranged to communicate with the trusted 
' arty device; 

at least one data storage device including storing the personal data of the user , said 
personal data comprising a master profile and one or more service profiles ; 

a rules enforcer included in the trusted party device to enforce rules by which the 
personal data of the user can be accessed and us e d b y a second party device, the rules having 
been agreed to by the user and a second party associated with the second party device, wherein: 
the at least one data storage device is associated with at least one of the user device and 
the trusted party device. 

19. (Presently Amended): The system of claim 18, further comprising a plurality of trusted 
party devices, each of the trusted party devices being configured to communicate with at least 
one other of the plurality of trusted party devices, and 

wherein the at least one storage device is included in at least some of the plurality of 
trusted party devices and the personal data of the user is distributed among the at least one 
storage device of the at least some of the plurality of trusted party devices. 

20. (Original): The system of claim 18, wherein the trusted party device further comprises 
an agreement facilitator to facilitate an agreement between the user and the trusted party. 

2 1 . (Original): The system of claim 1 8, wherein the user device further comprises an 
agreement facilitator to facilitate an agreement between the user and the trusted party. 
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22. (Presently Amended): The system of claim 18, wherein the second party comprises a 
financial institution, and wherein the identified service profile comprises financial 
mformation wherein th e at l e ast on e data storage device has recorded ther e in a servic e profil e 
within a personal data r e pository, wh e rein the service profil e includ e s portions of th e p e r s onal 
data of th e us e r and information r e garding conditions und e r which it e ms within th e service 
profil e can b e us e d by th e s e cond party . 

,23. (Presently Amended): The system of claim 18, wherein the trusted party device further 
comprises a history recorder to automatically record a history of actions performed by the user 
device. 

24. (Presently Amended): The system of claim 23, wherein the history recorder includes an 
action- level selector by which the user, via the user device, can s e l e ct on e of a plurality of l e v e ls 
of a typ e of define the actions to be automatically recorded. 

25. (Presently Amended): A system for providing personal data of a use r with access rights 
b e ing controll e d by th e us e r , the system comprising: 

a user device; 

a second party device, the user device being arranged to communicate with the second 
party device; 

a data storage, associated with the user device, including th e storing personal data of the 
use r, said personal data comprising a master profile and one or more service profiles : and 

a rules enforcer included in the user device to enforce rules by which portion s of th e 
p e r s onal data of th e us e rt he master profile and one or more service profiles can be accessed by 
the second party device, the rules having been agreed to by the user and a second party 
associated with the second party device, the rules including what items of the personal data are 
releasable to the second party and how the items of the personal data can be used by the second 
party. 
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26. (Presently Amended): The system of claim 25, wherein the second party comprises a 
financial institution, and wherein the identified service profile comprises financial 
informatio n furthcr comprising a se rvice profil e stor e d within tho data storag e , the service profil e 
including portions of th e p e rsonal data of th e u s er and information p e rtaining to an agr ee m e nt 
d e scribing how any of the stor e d information about th e us e r can be us e d by th e s e cond party . 

(21. (Presently Amended): The system of claim 25, wherein the user device further comprises 
a history recorder to automatically record a history of actions performed by the user device. 

28. (Presently Amended): The system of claim 27, wherein the history recorder includes an 
action-level selector to s e l e ct on e of a plurality of levels of a typ e o f define the actions to be 
recorded. / 

29. -34. Canceled) 

35. (Presently Amended) A mobile device for providing personal data of a user with access 
rights being controlled by the user, the mobile device comprising: 

a data storage device storing at least some personal data of the user, said personal data 
comprising a master profile and one or more service profiles; 

an agreement facilitator module to facilitate an agreement between the user and the 
second party according to which the second party can access the personal data; and 

a rules enforcer module to enforce the-rules by which the personal data of th e us e r can be 
accessed by a second party device , according to the agreement , th e rul e s having been agr ee d to 
by th e u s er and a second party associat e d with the second party d e vic e.t 

36. -44. (Canceled) 

45. (Previously amended) A mobile device for providing personal data of a user with access 
rights being controlled by the user, the mobile device comprising: 
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a rules enforcer to enforce the rules by which the personal data of the user can be 
accessed and used by a second party device, the rules having been agreed, to by the user and a 
second party associated with the second party device; 

a data storage device having recorded therein at least some of the personal data of the 

user; 

an agreement facilitator to facilitate an agreement between the user and the second party; 

and 

j a history recorder to record a history of actions by the user via the user device, the history 

recorder including a level selector to select a level of the actions to be recorded, wherein: 

I the data storage device is arranged to have recorded therein at least a portion of a service 

profile including information regarding what portions of the stored personal data of the user can 
be released to the second party and conditions under which the portions of the service profile can 
be released to the second party. 

46. - 47. (Canceled) 

48. (New): A computer readable medium storing computer executable instructions for 
performing a method for controlling access, use and distribution of personal data of a user stored 
in a personal repository, comprising the steps of: 

receiving input defining personal data comprising a master profile and one or more 
service profiles for storage in the personal repository, the master profile and one or more service 
profiles corresponding to the user; 

receiving user input identifying one of the service profiles stored in the personal data 
repository as corresponding to a second party; 

reaching an agreement, between the user and the second party, regarding release to the 
second party of the identified service profile; and 

providing the identified service profile from the personal data repository to the second 
party according to the agreement. 
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49. (New): The computer readable medium of claim 48, wherein the personal data comprises 
automatically collected information. 

50. (New): The computer readable medium of claim 48, wherein the step of reaching the 
agreement comprises choosing an agreement provided by an independent agreement provider, 
wherein the independent agreement provider receives compensation based on use of the provided 
agreement. 

5 1 . (New): The computer readable medium of claim 48, wherein the personal data comprises 
information entered by the user. 

52. (New): The computer readable medium of claim 48, wherein the computer executable 
instructions further comprise the step of storing the personal data on a device operated by the 
user. 

53. (New): The computer readable medium of claim 48, wherein the computer executable 
instructions further comprise the step of storing the personal data on a trusted party device. 

54. (New): The computer readable medium of claim 48, wherein the computer executable 
instructions further comprise the step of storing the personal data in a distributed manner among 
a plurality of trusted party devices. 

55. (New): The computer readable medium of claim 48, wherein the identified service profile 
comprises music preferences. 

56. (New): The computer readable medium of claim 48, wherein the second party comprises 
a financial institution, and wherein the identified service profile comprises financial information. 
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57. (New): The computer readable medium of claim 48, wherein the identified service profile 
includes information regarding a date and a time that any of the information in the identified 
service profile was released to the second party and to whom the stored information was 
released. 

58. / (New): The computer readable medium of claim 48, wherein the identified service profile 
includes information pertaining to a description of the agreement between the user and the 
second party. 

59. (New): The computer readable medium of claim 48, wherein the computer executable 
instructions further comprise the step of acting, by a trusted party, as an agent of the user to 
negotiate use, by the second party, of any of the personal data of the user in return for 
compensation to the user for the use of any of the personal data. 

60. (New): The computer readable medium of claim 49, wherein the computer executable 
instructions further comprise the steps of automatically recording a history of actions by the user 
using a user device, as part of the personal data of the user. 

61 . (New): The computer readable medium of claim 60, further comprising receiving user 
input defining a type of actions to be automatically recorded. 

62. (New): The computer readable medium of claim 48, further comprising the steps of: 
receiving, at a trusted party device connected to a computer network, a first request from 

a device operated by the user; 

forming a second request based on the first request, the second request being stripped of 
information that can associate the user with the second request; 

sending, from the trusted party device, the second request over a computer network to a 
second party device; 
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receiving, at the trusted party device, response information in response to the sending of 
the second request; 

forming a response based on the response information; and 
sending the response to the device operated by the user. 
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